Case Study
Case Study: Cyber Essentials Plus Audit Pass First Time
Published 30 April 2026
The brief
A 60-staff professional services firm. They held Cyber Essentials but their largest client (a UK regulator) now required Cyber Essentials Plus annually. Audit had to be passed within 6 weeks to retain the contract.
Pre-audit readiness check
Our readiness review identified five issues likely to fail the formal audit:
- Patches were within policy but evidence was not centrally retained
- Two admin accounts could read email and browse the web
- Microsoft 365 legacy authentication was not fully blocked
- Anti-malware was disabled on three sample devices
- One macOS device was on an unsupported version
The 4-week remediation programme
- Week 1 – Intune patch reporting enabled, retained for 90 days. macOS device upgraded.
- Week 2 – Admin accounts separated. New cloud-only admin accounts created with hardware security keys, blocked from Outlook and browser via Conditional Access.
- Week 3 – Legacy authentication fully disabled. Anti-malware re-enabled and monitored centrally via Defender for Endpoint.
- Week 4 – Mock audit run. All sample devices passed. Email/web malware tests passed.
The audit
The formal CE Plus audit ran across 2 days remotely. External vulnerability scan: clean. Authenticated device scan on 6 sample devices: all patched, all anti-malware running. Email and web download tests: all malicious payloads blocked. MFA verification: enforced on every account including the new admin accounts. Result: zero findings, first-time pass.
The outcome
- Cyber Essentials Plus issued, valid 12 months
- Contract retained with the regulator
- Client now uses the same controls evidence to satisfy 4 other tender questionnaires
